top_left top_right
bottom_left
Next Event: Unknown | Forum Rules | QGL Website | Event Registration
openFolder AusForums.com
iconwatfolderLineopenFolder LANs
iconwatfolderLineopenFolder QGL
iconwatfolderLineopenFolder QGL Forum
Author
Topic: Try to hack!
teen
Posts: 6364
Location: Brisbane, Queensland
itm sent me this site
Where you get challenges and have to hack in to the next challenge.
I only just started
system
--
dais
Posts: 4035
Location: Brisbane, Queensland
old :]
Skitza
Posts: 835
Location: Brisbane, Queensland
very old and boring :)
teen
Posts: 6365
Location: Brisbane, Queensland
woooo level 3 muthabitches!
teen
Posts: 6366
Location: Brisbane, Queensland
level 4!!! hahah reet
HerbalLizard
Posts: 881
Location: Brisbane, Queensland
If I didn't have a f***ing huge assginment due I would be playing wargames but alas asignment is due tommrow
phathead
Posts: 308
Location: Brisbane, Queensland
Level 6 - i give up, this is too hard
HerbalLizard
Posts: 882
Location: Brisbane, Queensland
Level two
User name: Try2Hack
Password: NokiaIsGood
Hemerage
Posts: 3126
Location: Brisbane, Queensland
i cant code, hack or do any of that s*** ... and never want to

but someone gave me a few pointers and i think i got to Lv5 once

too boring for me :)
teen
Posts: 6367
Location: Brisbane, Queensland
why are you posting answers? don't be an a******
HerbalLizard
Posts: 884
Location: Brisbane, Queensland
Better yet would you like to see how I did it so that others can learn? Or should I wait for the others to catch up.

Anyway here is a hint
// <<<<<<<< Have a look here
//gaybo script
phathead
Posts: 310
Location: Brisbane, Queensland
spam +1
EvisceratoR
Posts: 2377
Location: Brisbane, Queensland



gayyyyy
phathead
Posts: 311
Location: Brisbane, Queensland
spammage
EvisceratoR
Posts: 2378
Location: Brisbane, Queensland
herbal can't code...
HerbalLizard
Posts: 887
Location: Brisbane, Queensland
Sorry Teen I f***ed up your thread. :/

I'll remmber to comment s*** out next time
HerbalLizard
Posts: 888
Location: Brisbane, Queensland
So Evis you want to prove you can?
EvisceratoR
Posts: 2380
Location: Brisbane, Queensland
just put [/script] in ur post, u forgot to put it in...
EvisceratoR
Posts: 2381
Location: Brisbane, Queensland
but I have no idea otherwise...
HerbalLizard
Posts: 889
Location: Brisbane, Queensland
Thanks Evis this forum is different form some of the other forums I use for posting code snippets
EvisceratoR
Posts: 2382
Location: Brisbane, Queensland
there I fixed it lol

I have ur name and shti in my post :P
HerbalLizard
Posts: 890
Location: Brisbane, Queensland
Thanks for fixing it but can you just remove the script

Edit: and your little comment please
ex!stence
Posts: 1512
Location: Brisbane, Queensland
herbillizard, can you please ICQ me on 82763218 or MSN on i_ownj_u@hotmail.com

thx
Reaperman
Posts: 27
Location: Queensland
he can someone teach me this stuff
i did the first lvl easy as hell and i wanna know how to do the second
dont just give me the password i wanna learn
teen
Posts: 6369
Location: Brisbane, Queensland
I guess the first clue to give you reaperman is that you're going to have to go to some effort to find the password. What's different about level 2 than level 1? Think about that.


Someone give me a clue for level 4. What does 'local1' do? Is it relevant? I have several theories on what the username/password are but they all contradict each other. I'm guessing the username and password are derived from each other somehow.
HerbalLizard
Posts: 891
Location: Brisbane, Queensland
Hint: Your on the right track you have to decompile the binary usin javap out of the Java Development Kit (I think thats what JDK stands for)

Using the inFile() method look for string #15 and you guessed it its 'level4' then think what you will do next. Think url!

I'm thinking how to rip up level five which happens to be an .exe. I'm thinking WinHex32 might do the job. I'll have a look at this over the weekend I still can not break level 5 yet
HerbalLizard
Posts: 892
Location: Brisbane, Queensland
I Soooooo hate java programing.
Reaperman
Posts: 29
Location: Queensland
righto well its obvious its in flash but what can i do? download it and check it or something? i checked the source code like the first but that obviously is wrong
HerbalLizard
Posts: 893
Location: Brisbane, Queensland
Reaperman I will give you another hint. You need to get the contents of the flash file and sort through the code

*************************************************
/contents of the file pasted from notepad
*************************************************
FWS¯ p   »€  C 3™?    Courier New   *  wû ݰ­0 à Ìÿÿ ( Username :
‰  ¯  *  wû ݰ­0 à Ìÿÿ ( Password :
Š  +Ä~ ?\  eË#_B à¹Äk@ ÿÿÿ ÿ €5oßzs
àìàö0ß>(ß[ tR öî;)>/" ±N ±r3r
Pu‡ªÖüêPØà ?‘  eôßS
H©–Mhœ'[W  ÿÿÿÖÿÿÿÿ ÿ+++ÿ­¹$ú`ÅUÌ>ˆ ÿÿÿÖÿÿÿÿ ÿ+++ÿ —Õð4½â:‰1ÎÏ<Ë\èÃ3"ŒžJ!äw“cžÓ
ML1wÑ5×?Æ «rÂÍ”øà¨$ù—)ÚâöÛý˃‡Ì2y QÊk®Ò©ì€€ ?&  eË#_B à fÿÿ ÿoßzg:À ÙÀ ìa¾|Q¾¶ è¤ìÜvR|^Dbœc:äg:ä  ëU·ÿùÓÀC‘°µ¸þYÌÒ° ù0äºÌùb½°ÑZSÜ?Ù­\×}6rö¸Ì ,Š»0½’F$æBT!ꣿÿ:P j,> ¹„À ÿÿÿ ÿ fÿÿ €!5oßzYΆðvp{oŸo­€:){÷”Ÿ‘ X§ Xιι(:ÃÕmÿþtðäln?–LÍ+ “ >K¬Ï–+Û ¥=ÃýšÕÍq‡Óg/k€,ÊÈ«³ Ù$bgV'3lÀ éUÿùÒ€Q` ?ð  \P– ¹„À ÿÿÿ ÿ €5n?–s4¬ >L ù.³>X¯l tV”÷ökW5ÆMœ½® ³( "®Ì/d‘‰9§P• gHz¨ïÿΔ ‹„ ©–Mhœ'[C€ ÿÿÿÖÿÿÿÿ ÿ+++ÿ n'å>8* ~geÊv¸½¶ÿràáó žBÔršÄ«´ª{ ø@­¹$ú`ÅUÏÿ  ÿÿÿÖÿÿÿÿ ÿ+++ÿ q_¢æ9ÃYç™kfdQ€“ÉD<ŽòlsÚa©©†.ú&ºçøÄ—¼GQ ¿ H  eË#_B à 3Ì oßzg:À ÙÀ ìa¾|Q¾¶ è¤ìÜvR|^Dbœc:äg:ä  ëU¬ÿùÔ ±À ¿ &             –
txtUsername – Try2Hack -===HINT===-
txtPassword – NokiaIsGood -===HINT===-
I  ƒ LLeVeLL3.html _self  ÉuÝUå>UC ¿ ]
pSÎ[Ì~p½£Š€_TÝ  ÿÿ  -ÍáøVEì hd|ôT€—8–»GÐ^’Pà¨P ]î¯n ¬à ­áF‹¸ÞÀ ‰
ýÈ + wû
@ÿ°@  à Ìÿÿ  ( txtUsername Ž É ž>’ OE4†
 + wû
¸ÿ°@  à Ìÿÿ  ( txtPassword Š
Pfe @
**************************************************
Reaperman
Posts: 30
Location: Queensland
thanx guys
i really should refresh the forum before i post crap
HerbalLizard
Posts: 894
Location: Brisbane, Queensland
Also I need help with the core crackme its f***ing uber hard to crack
fubar
Posts: 442
Location: Brisbane, Queensland
this is gay i can't get lvl 2
i did

user:::: Try2Hack
pass:::: NokiaisGood

any way how did you figure that out
HerbalLizard
Posts: 896
Location: Brisbane, Queensland
In the script it calls FlashLevel2.swf one of my previous posts shows the contents of the file. Half the bloody trouble is saving the flash file. I'll let you stew that over for a while
Borat
Posts: 31
Location: Brisbane, Queensland
im stuck on lvl 3 :( i thought i got it straight away but they were being sneaky. any hints?
Reaperman
Posts: 33
Location: Queensland
im completely stuck on lvl 3 as well
teen
Posts: 6371
Location: Brisbane, Queensland
level 3 was easy! hint - get the password wrong first, then go from there.
HerbalLizard
Posts: 899
Location: Brisbane, Queensland
teen have you had any luck with level 4 yet I need some help with 5
teen
Posts: 6372
Location: Brisbane, Queensland
no but I can sense I'm close to it.. there are just a few things I don't understand in the code
cobz
Posts: 326
Location: Sydney, New South Wales
level 7, this is where you have to start decompiling s***.

Theres a better one in japan where the admin placed holes and some backdoors in his server that you need to exploit to get your name on the hall of fame, cant remember the url though :|
Ice
Posts: 76
Location: Brisbane, Queensland
Can someone Tell me if the level 3 password is:

AbCdE

Cause in the source it says it is, and it wont work for me
HerbalLizard
Posts: 902
Location: Brisbane, Queensland
cobz checkout wargames at HDC BBS
http://www.hackers.com/________.________/ yes thats the url really. They have a few linux based systems to crack

Teen your really close I can tell you that much. What part are you having trouble with.

I have so got to pick up my act in regards to coding
teen
Posts: 6373
Location: Brisbane, Queensland
No, that's NOT The Correct Answer, Ice

clicky
there should be a link there for "no preview"

teen
Posts: 6374
Location: Brisbane, Queensland
I don't get the for loop and the if statement following it. It looks to me like the password is just the username with more characters in it, and I know it's matching it up with an array that may have 'level4' written in it.
Then it refreshes to a URL based on the password - so maybe you don't have to type a password in just figure out the url...
Ice
Posts: 78
Location: Brisbane, Queensland

Found level 3
cobz
Posts: 327
Location: Sydney, New South Wales
herbal i remember writing a basic article on how to get around restrictions in mac computers there (my schools second computer room :) is that a hidden board? looks like it, the one i used to visit was full of people asking how to hack hotmale.
I found a weird exploit in novell netware yesterday, flooding the /perl/samples/ndslogin.pl path with logins will crash the server. http://www.woodleigh.vic.edu.au/perl/samples/ndslogin.pl what the form looks like. If any admin reads this and gets paranoid..i dont f*** with webservers i actualy enjoy visiting.



cobz
Posts: 328
Location: Sydney, New South Wales
test (may have borked my links)
HerbalLizard
Posts: 906
Location: Brisbane, Queensland
Oh no It wasn't you it was me because I f***ed up when I was commenting some code YET AGAIN. And I burnt my dinner which pisses me off
Ice
Posts: 80
Location: Brisbane, Queensland
Need help on level 4 :)

Someone help me with the java class file please :)

totno = totno + 1;
inuser[totno] = local1;
local1 = "";

it checks inuser to make the username inuser[2] and the password inuser[3]
but assigns both of these local1, which = "" nothing :(.

No password and username?
teen
Posts: 6376
Location: Brisbane, Queensland
I wanna know where local1 is declared - NOWHERE
hast
Posts: 122
Location: Brisbane, Queensland
mmm level 4 hint

1. download jad
2. decompile
3. look at source code and see inFile="level4"
4. download "level4" file
5. notice "
http://www.try2hack.nl/5_level_5.html"
6. go to that url
HerbalLizard
Posts: 907
Location: Brisbane, Queensland
The code base for the applet is http://www.try2hack.nl/ so just add inFile="level4 to the url http://www.try2hack.nl/level4 right click then view source what do you see.
teen
Posts: 6377
Location: Brisbane, Queensland
hast - I don't follow your logic - what is "download level4 file" mean?
teen
Posts: 6378
Location: Brisbane, Queensland
"view source" ?? that doesn't work on this site...

I tried going to that url but it's a blank page, when I download it i get this:




<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0
Transitional//EN">



<!-- saved from url=(0029)http://www.try2hack.nl/level4
-->



<HTML><HEAD>



<META http-equiv=Content-Type content="text/html;
charset=windows-1252">



<META content="MSHTML 6.00.2719.2200" name=GENERATOR></HEAD>



<BODY><PRE></PRE></BODY></HTML>



HerbalLizard
Posts: 908
Location: Brisbane, Queensland
My arse it doesn't try right click on the link then view source

This is what I found

5_level_5.html

Username Try2Hack
Password: AppletsAreEasy
teen
Posts: 6379
Location: Brisbane, Queensland
and for the record I tried going to 'level4' almost immediatly when I read the code.

I've been sitting here drawing up f***ing traces of the algorithm, and trying to figure out how the password is encoded using that offsetting method they have f*** you all for having non-broken computers,.
HerbalLizard
Posts: 909
Location: Brisbane, Queensland
bump
Contents of level4
5_level_5.html
Try2Hack
AppletsAreEasy
teen
Posts: 6380
Location: Brisbane, Queensland
My arse it doesn't try right click on the link then view source


Nope that doesn't work.
These challenges would actually be pretty f***ing easy if you could see the source.
Ice
Posts: 81
Location: Brisbane, Queensland
i got it, with that lil help :P
HerbalLizard
Posts: 912
Location: Brisbane, Queensland
Does that explain much
Ice
Posts: 82
Location: Brisbane, Queensland
Someone tell us about level5

Username=AlmostAHacker
Password=ZqrE01A2d

is that false? a fake one :( damnit doesnt work for me
HerbalLizard
Posts: 913
Location: Brisbane, Queensland
Its false as far as I can see
Ice
Posts: 83
Location: Brisbane, Queensland
well im pretty much f***ed now :)
HerbalLizard
Posts: 914
Location: Brisbane, Queensland
Same here I will have a look how it uses memory and see if caputuring some snapshots will help.
teen
Posts: 6381
Location: Brisbane, Queensland
Level 6 (NOT !)



Did you really think it would be this easy ? Go back and try again !


lool
HerbalLizard
Posts: 915
Location: Brisbane, Queensland
I tried a couple of vb decompilers on it alas no joy so I was thinking
enter a value and see how it is passed into memory and take a snapshot with a hex editor and look for that same value
teen
Posts: 6382
Location: Brisbane, Queensland
I got it! Try to hack out of inspiration!
Ice
Posts: 84
Location: Brisbane, Queensland
I cant take snapshot of memory something about too many addresses :(
HerbalLizard
Posts: 916
Location: Brisbane, Queensland
how care to explain
teen
Posts: 6383
Location: Brisbane, Queensland
clue: look up what Mid() does
HerbalLizard
Posts: 917
Location: Brisbane, Queensland
thanks
Hemerage
Posts: 3142
Location: Brisbane, Queensland
i stopped when it said to download something so i could decompile .... not a chance in hell id even consider it

with the flash password ones ... is that just how his is setup?

surely u cant just get into stuff that easy :)

i guess his password is just linked to an invisible field in his flash movie
HerbalLizard
Posts: 918
Location: Brisbane, Queensland
What decompiler did you use
teen
Posts: 6385
Location: Brisbane, Queensland
ftp://ftp.one.net/pub/users/dreitz/decompiler/vbdis22e.zip
teen
Posts: 6386
Location: Brisbane, Queensland
not a chance in hell id even consider it


Get out of your diapers you f***ing baby - be a man - download an EXE file created in VB.
Ice
Posts: 85
Location: Brisbane, Queensland
herbal lizard fs, fix your sig it keeps borking the thread
Hemerage
Posts: 3145
Location: Brisbane, Queensland
teen: i dont have any progs which do this stuff.... wouldnt know where to start

NEVER want to learn it ... ill stick to 3D thx
Ice
Posts: 86
Location: Brisbane, Queensland
Can someone give us a crash course in how to work that vb decompiler.. i keep gettings errors VB is not instaleld and how do i save a *.frm file as a *.txt file
teen
Posts: 6387
Location: Brisbane, Queensland
Ice, i get the same errors... just chose 'combine forms' from the menu... then use wordpad to open the files it's output - one of them had pretty coherent code in it.
HerbalLizard
Posts: 919
Location: Brisbane, Queensland
I just figured it out with that decompiler you recommended teen c001A has a set of aphlanumerical values as well as .,:;-*+=~|&!_$#@()[]{}<\/> which are shown in the level5.bas file.

Each of the varibles coresponses to the vaules in c001A for txtUsername and txtPassword. There has to be a easier way instead of counting each of these vaule and matching the varibles
HerbalLizard
Posts: 920
Location: Brisbane, Queensland
*hint level5.bas
HerbalLizard
Posts: 921
Location: Brisbane, Queensland
Thats it use the Const mc001A = "0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ.,:;-*+=~|&!_$#@()[]{}<\/>"
to match each instance of mc001A
mc001A, 56 = T
mc001A, 28, = r
mc001A, 35, = y

= Try and so on and so on

etc etc simply count across from 0123... until you reach the value in each instance of mc001A

Ice
Posts: 88
Location: Brisbane, Queensland
f*** finnaly

Try2Hack
OutOfInspiration
teen
Posts: 6391
Location: Brisbane, Queensland
yes that's it :P It didn't take me long to find them, because in ms word it tells you which column your cursor is in.
HerbalLizard
Posts: 922
Location: Brisbane, Queensland
the proxy in 6 wtf. Got any good any ideas on how to attack it?
teen
Posts: 6393
Location: Brisbane, Queensland
well I've been looking at the .exe file in wordpad and there are a few clues as to the software used to compress the program, perhaps uncompressing it with the same utility will make it decompilable again.
Also perhaps hex editting or something will help reveal the mystery.

but it's late so I'm going to leave it for another time :P
HerbalLizard
Posts: 923
Location: Brisbane, Queensland
It must send an authenication request back to the server and its susposidly protected any ideas
Ice
Posts: 89
Location: Brisbane, Queensland
um yeah, you can't decompile VB5 and VB6... so wtf
HerbalLizard
Posts: 924
Location: Brisbane, Queensland
Uhhhmmm you want to try with the hex editor I'll see what travels through the IDS on smoothwall see if authenication is done client side or server side. Me prays client.
HerbalLizard
Posts: 925
Location: Brisbane, Queensland
Or even WinDASM32 might do it
teen
Posts: 6394
Location: Brisbane, Queensland
There is only place the clues are accessible to you though - and that's in the .exe file.... maybe we won't able to see the source, but there is some way to look at it I bet.
Ice
Posts: 90
Location: Brisbane, Queensland
Im off to sleep ;) exams today, f*** this thing i would have gone to sleep ages ago :)
thrax
Posts: 886
Location: Brisbane, Queensland
Played around with it for a while, lost intrest in the frist 5 sec's.
HerbalLizard
Posts: 926
Location: Brisbane, Queensland
Teen I'll give it another crack next week when I have some holies thank f***.
Ice
Posts: 92
Location: Brisbane, Queensland
Anyone get level 6 yet, im using Etheral as the packet sniffer but it says its encrypted and i dont know the cypher :(
tim...
Posts: 60
Location: Brisbane, Queensland

I am up to level 8

sooo reet
Ice
Posts: 93
Location: Brisbane, Queensland
Give us help with level 6 it says encryped! :( And i dont know how to find the cypher.. eg.

GET /p.lv6 HTTP/1.1
Connection: KeepAlive-Alive
User-Agent: Mozilla/4.0
Accept: "/"

HTTP/1.1 200 OK
Date: ...
Server: Apache
yadah yadah yadah

Content-Type: text/plain

.(ENCRTPTION TYPE)
B*C*N**N

(USERNAME)
ababa abbab baaaa aaabb

(PASSWORD
ababa aaaaa abbaa abbba aaaa baaaa babba

then Page etc..

Help me :)
tim...
Posts: 61
Location: Brisbane, Queensland
well the user name and password are encrypted in a specific format....I am not sure what more I can help...google it mang...thats what google is there for
Zekts
Posts: 831
Location: Brisbane, Queensland
screw this, I'm just gonna stick to 3d like Hem. I cant be bothered decompiling and so on just so I can say I am reet.
Ice
Posts: 95
Location: Brisbane, Queensland
Ok level 8 now got level 7

Someone tell me how to work in the phf cgi exploit. :)
HerbalLizard
Posts: 948
Location: Brisbane, Queensland
Ice how did you crack level 6 I havn't look at it since last week
teen
Posts: 6638
Location: Brisbane, Queensland
I actually looked at lvl 6 today, I couldn't get the packet sniffer to work tho.
my hard drive got trashed a few minutes later, so I won't be hitting it for a while.
HerbalLizard
Posts: 950
Location: Brisbane, Queensland
I tryed a sniffer but its encrypted with some weird s***...any idea yet all I get is the same as what ICE posted.

On of my tutors is stuck on 9 the only hint he will give me is that its in the encryption. Yeah well dah but what to do from there. Maybe have a look at it with a hex editor...I'm going to have a chat with him tommrow and find out what he did.
HerbalLizard
Posts: 951
Location: Brisbane, Queensland
My tutor also said that he might make it a class project for my manage security subject. Go figure
system
--
Not a new post since your last visit.
New Post Since your last visit
Back To Forum
Advertise with Us | Privacy Policy | Contact Us
© Copyright 2001-2026 AusGamers Pty Ltd. ACN 093 772 242.
Hosted by Mammoth Networks - Australian VPS Hosting
Web development by Mammoth Media.